CVE-2022-20845 is a medium-severity memory leak vulnerability affecting the TL1 function in Cisco Network Convergence System (NCS) 4000 Series. An authenticated, local attacker can exploit this by issuing specific TL1 commands, causing the TL1 process to consume excessive memory. This leads to a denial of service (DoS) as the Resource Monitor restarts or shuts down memory-intensive processes. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cisco | Cisco IOS XR Software | 6.5.25, 6.5.26, 6.5.28, 6.5.29, 6.5.31, 6.5.32CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.